Attor

S0438

Malware.View on attack.mitre.org

About this malware

Attor is a Windows-based espionage platform that has been seen in use since 2013. Attor has a loadable plugin architecture to customize functionality for specific targets.

Techniques used35

Procedure examples35

TechniqueProcedure example
T1010
Application Window Discovery

Attor can obtain application window titles and then determines which windows to perform Screen Capture on.

T1012
Query Registry

Attor has opened the registry and performed query searches.

T1020
Automated Exfiltration

Attor has a file uploader plugin that automatically exfiltrates the collected data and log files to the C2 server.

T1027.013
Encrypted/Encoded File

Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA.

T1036.004
Masquerade Task or Service

Attor's dispatcher disguises itself as a legitimate task (i.e., the task name and description appear legitimate).

T1037.001
Logon Script (Windows)

Attor's dispatcher can establish persistence via adding a Registry key with a logon script HKEY_CURRENT_USER\Environment "UserInitMprLogonScript" .

T1041
Exfiltration Over C2 Channel

Attor has exfiltrated data over the C2 channel.

T1053.005
Scheduled Task

Attor's installer plugin can schedule a new task that loads the dispatcher on boot/logon.

T1055
Process Injection

Attor's dispatcher can inject itself into running processes to gain higher privileges and to evade detection.

T1055.004
Asynchronous Procedure Call

Attor performs the injection by attaching its code into the APC queue using NtQueueApcThread API.

T1056.001
Keylogging

One of Attor's plugins can collect user credentials via capturing keystrokes and can capture keystrokes pressed within the window of the injected process.

T1070.004
File Deletion

Attor’s plugin deletes the collected files and log files after exfiltration.

T1070.006
Timestomp

Attor has manipulated the time of last access to files and registry keys after they have been created or modified.

T1071.002
File Transfer Protocols

Attor has used FTP protocol for C2 communication.

T1074.001
Local Data Staging

Attor has staged collected data in a central upload directory prior to exfiltration.

View all 35 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. ESET Attor Oct 2019 Open source
    Hromcova, Z. (2019, October). AT COMMANDS, TOR-BASED COMMUNICATIONS: MEET ATTOR, A FANTASY CREATURE AND ALSO A SPY PLATFORM. Retrieved May 6, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.